VulnSea

Daily digest

Friday 19 June 2026

A heavy day: 202 new CVEs, well above the recent average of about 91. Severity skewed high: 16 critical and 93 high, 54% of the total. 3 arrived with exploitation evidence or public exploit code already attached. CoreWCF was the most-affected vendor with 13.

202
New CVEs
16
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 202 published.

CVE-2026-55255Critical· 9.9CISA KEVPoC
3mo ago

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

▾ Hadallangflow · langflowEPSS 0.89%via GHSA
CVE-2026-54782Critical· 10.0
3mo ago

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

▾ MidnightCoreWCF · CoreWCF.PrimitivesEPSS 0.41%via GHSA
CVE-2026-54051Critical· 9.9
3mo ago

Network-AI: Improper Neutralization of Special Elements used in an OS Command

Network-AI: Improper Neutralization of Special Elements used in an OS Command

▾ Midnightnetwork-ai · network-aiEPSS 0.67%via GHSA
CVE-2026-52910High· 7.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro

In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro. [0] The repro sets up a UDP reuseport group with a cBPF prog a…

▾ Midnightlinux · linux_kernelEPSS 0.11%via NVD
CVE-2026-48584Critical· 9.9
3mo ago

Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_synapseEPSS 0.91%via NVD
CVE-2026-45480Critical· 10.0
3mo ago

Azure Active Directory Elevation of Privilege Vulnerability

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Active DirectoryEPSS 0.90%via CVEORG
CVE-2026-54414Critical· 9.8
3mo ago

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by F…

▾ MidnightEPSS 0.66%via NVD
GHSA-h3m5-97jq-qjrfCritical· 9.6
3mo ago

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

▾ Midnightopenremote · io.openremote:openremote-managervia GHSA
CVE-2026-56120Critical· 9.6
3mo ago

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

▾ Midnightopenremote · io.openremote:openremote-managervia GHSA
CVE-2026-55447Critical· 9.6
3mo ago

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

▾ Midnightlangflow · langflowEPSS 0.66%via GHSA
CVE-2026-54900HighPoC
3mo ago

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

▾ Midnightoj · ojEPSS 0.43%via GHSA
CVE-2026-48582Critical· 9.6
3mo ago

Microsoft Exchange Online Elevation of Privilege Vulnerability

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Exchange OnlineEPSS 0.69%via CVEORG

Most-affected vendors

By CVEs published in the period.